1 Answer
- Newest
- Most votes
- Most comments
2
While you are sharing the VPC (or rather the subnet of it), you are not sharing the resources like ALB deployed into subnet(s).
Participants cannot view or modify resources that belong to other participant accounts.
PrivateLink would allow you to build the solution you have drawn. See https://aws.amazon.com/blogs/apn/enabling-new-saas-strategies-with-aws-privatelink/
Relevant content
- Accepted Answerasked 10 months ago
- asked 2 years ago
- AWS OFFICIALUpdated 19 days ago
- AWS OFFICIALUpdated 9 months ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated a year ago
There is a guide https://aws.amazon.com/blogs/compute/building-private-cross-account-apis-using-amazon-api-gateway-and-aws-privatelink/ describes how to achieve that in situation when "VPCs are not shared" It makes sense... But in my case - VPC is the same, all services sit in one VPC anyway... But there is no possibility (as far as I can see) to use one single NLB & ALB for all ESC services in all accounts...